VDB
BDU%3A2024-06665
BDU%3A2024-06665
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции mod_css_styles компонента Cascading Style Sheet Handler почтового клиента RoundCube, позволяющая нарушителю раскрыть конфиденциальную информацию
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| Сообщество свободного программного обеспечения, ООО «Ред Софт», The RoundCube Team | Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), RoundCube Webmail | |
| roundcube | roundcube | 0, 1.6x |
Timeline
- Aug 5, 2024 CVE Published
- Aug 5, 2024 PoC Published
- Dec 3, 2024 CVE Updated
- Feb 13, 2025 PoC Published
- Jul 12, 2026 PoC Published
- Jul 13, 2026 PoC Published
- Jul 14, 2026 PoC Published
References
- https://github.com/roundcube/roundcubemail/releases url
- https://redos.red-soft.ru/support/secure/ url
- https://sonarsource.com/blog/government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail/ url
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.8 url
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.8 url
- https://roundcube.net/news/2024/08/04/security-updates-1.6.8-and-1.5.8 url
- https://security-tracker.debian.org/tracker/CVE-2024-42010 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory